Hacker News new | ask | show | jobs
by zahraarman 9 days ago
The root issue generalizes past Claude Code: permission enforcement that lives inside the tool it's supposed to police will always be one bug away from failing open. The only version of this I trust is a check that happens outside the process, on the actual call, with a log of why it was allowed.